<!-- enforcing policy:
script-src 'self' 'unsafe-inline' blob:; connect-src 'self';
blob: URLs are same-origin with the page in which they were created, but match only if the blob: scheme is specified.
function pass() {
log("PASS (1/1)");
var b = new Blob(['pass();'], {
type: 'application/javascript'
var script = document.createElement('script');
script.src = URL.createObjectURL(b);
<div id="log"></div>
